@@ -90,9 +91,10 @@ function getParticipantsIdentifiants(req, res){
functiongetParticipantsById(req,res){
varcon=mysql.createConnection(dbConfig);
varquery="SELECT id,name FROM Participant WHERE deleted = 0 AND id = '"+req.query.id+"' ORDER BY NAME ASC;"
varquery="SELECT id,name FROM Participant WHERE deleted = 0 AND id = ? ORDER BY NAME ASC;"
varinserts=[req.query.id];
con.connect();
con.query(query,(err,result)=>{
con.query(query,inserts,(err,result)=>{
if (err){
console.log(err)
returnres.send({success:false})
...
...
@@ -104,9 +106,10 @@ function getParticipantsById(req, res){
functiongetResultatsPersonnels(req,res){
varcon=mysql.createConnection(dbConfig);
varquery="SELECT Participant.id as id, Participant.name as name, score, Equipe.name AS equipe_name, createdAt AS date FROM Score JOIN Participant ON Participant.id=Score.participantId JOIN Equipe ON Score.equipeId = Equipe.id WHERE (Score.deleted = 0 AND ( Participant.deleted=0 AND Participant.id='"+req.query.id+"')) ORDER BY date ASC;"
varquery="SELECT Participant.id as id, Participant.name as name, score, Equipe.name AS equipe_name, createdAt AS date FROM Score JOIN Participant ON Participant.id=Score.participantId JOIN Equipe ON Score.equipeId = Equipe.id WHERE (Score.deleted = 0 AND ( Participant.deleted=0 AND Participant.id=?)) ORDER BY date ASC;"
varinserts=[req.query.id];
con.connect();
con.query(query,(err,result)=>{
con.query(query,inserts,(err,result)=>{
if (err){
console.log(err);
returnres.send(
...
...
@@ -151,9 +154,10 @@ function getResultatsPersonnels(req, res){
functionaddNewParticipant(req,res){
varcon=mysql.createConnection(dbConfig);
varquery="INSERT INTO `Participant` (`name`) VALUES ('"+req.body.name+"');"
varquery="INSERT INTO `Participant` (`name`) VALUES (?);"
varinserts=[req.body.name];
con.connect();
con.query(query,(err,result)=>{
con.query(query,inserts,(err,result)=>{
if (err){
console.log(err)
returnres.send({success:false})
...
...
@@ -165,9 +169,10 @@ function addNewParticipant(req, res){
functionaddNewParticipantWithId(req,res){
varcon=mysql.createConnection(dbConfig);
varquery="INSERT IGNORE INTO `Participant` (`id`, `name`) VALUES ('"+req.body.id+"','"+req.body.name+"');"
varquery="INSERT IGNORE INTO `Participant` (`id`, `name`) VALUES (?,?);"
varinserts=[req.body.id,req.body.name];
con.connect();
con.query(query,(err,result)=>{
con.query(query,inserts,(err,result)=>{
if (err){
console.log(err)
returnres.send({success:false})
...
...
@@ -179,9 +184,10 @@ function addNewParticipantWithId(req, res){
functionupdateParticipant(req,res){
varcon=mysql.createConnection(dbConfig);
varquery="UPDATE Participant SET name = '"+req.body.name+"' WHERE id="+req.body.id+";"
varquery="UPDATE Participant SET name = ? WHERE id=?;"
varinserts=[req.body.name,req.body.id];
con.connect();
con.query(query,(err,result)=>{
con.query(query,inserts,(err,result)=>{
if (err){
console.log(err)
returnres.send({success:false})
...
...
@@ -193,9 +199,10 @@ function updateParticipant(req, res){
functiondeleteParticipant(req,res){
varcon=mysql.createConnection(dbConfig);
varquery="UPDATE Participant SET deleted = 1 WHERE id='"+req.body.id+"';"
varquery="UPDATE Participant SET deleted = 1 WHERE id=?;"